CVE-2020-26223
Estado: ModificadaMedia (6.5)—
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.12%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
- https://github.com/spree/spree/pull/10573
- https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr
- https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status
- https://github.com/spree/spree/pull/10573
- https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr
- https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-26223",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "spree",
"product": "spree",
"versions": [
{
"status": "affected",
"version": ">= 3.7.0, < 3.7.13"
},
{
"status": "affected",
"version": ">= 4.0.0, < 4.0.5"
},
{
"status": "affected",
"version": ">= 4.1.0, < 4.1.12"
}
]
}
]
}
],
"published": "2020-11-13T18:15:12.777",
"references": [
{
"url": "https://github.com/spree/spree/pull/10573",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/spree/spree/pull/10573",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected."
},
{
"lang": "es",
"value": "Spree es una completa solución e-commerce de código abierto construida con Ruby on Rails. En Spree desde la versión 3.7 y versiones anteriores a 3.7.13, 4.0.5 y 4.1.12, se presenta una vulnerabilidad de omisión de autorización. El perpetrador podría consultar el endpoint API v2 Order Status con una cadena vacía pasada como un token de pedido. Esto está parcheado en versiones 3.7.11, 4.0.4 o 4.1.11 dependiendo de la versión de Spree usada. Los usuarios de Spree versiones anteriores a 3.7 no están afectados"
}
],
"lastModified": "2026-06-17T03:07:51.423",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F0DFB4E-3D62-4C6C-A227-3B839055F34C",
"versionEndExcluding": "3.7.13",
"versionStartIncluding": "3.7.0"
},
{
"criteria": "cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B10057D2-194D-4019-A8F3-9A64E3BAFE70",
"versionEndExcluding": "4.0.5",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95279953-3BEB-454E-8C60-F4E00602849B",
"versionEndExcluding": "4.1.12",
"versionStartIncluding": "4.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}